Built for financial institution security requirements
Caspix is designed for deployment inside regulated financial institutions. Access controls, audit logging, encryption, and deployment flexibility are structural — not add-ons.
Role-based access across every function
Access is determined by role, not by individual configuration. Permissions cannot accumulate silently over time.
Role-Based Access Control (RBAC)
Every user is assigned a role with a defined permission set. Analysts, investigators, managers, and administrators each have access scoped to their function — no lateral access between roles.
Least Privilege by Default
Permissions are assigned by role, not accumulated over time. Role changes take effect immediately. Off-boarding revokes access in one operation.
Audit-Logged Authentication
Every login, failed attempt, session expiry, and privilege escalation is captured in the audit log with timestamp, IP, and user attribution.
Role-Gated Destructive Operations
High-impact actions — entity registry removals, rule retirement, case closure — require elevated roles. The system prevents accidental or unauthorized changes through structural controls, not policy alone.
Encryption in transit and at rest
Customer data is protected at every layer — in transit, at rest, and in application output.
TLS 1.3 in Transit
TLS 1.3All data in transit between clients and the platform is encrypted using TLS 1.3. Older protocol versions are not negotiated.
Encrypted at Rest
AES-256Transaction records, case data, and audit logs are encrypted at rest using AES-256. Encryption keys are managed separately from the data they protect.
Secrets Management
Env-IsolatedApplication secrets — API keys, database credentials, SMTP configuration — are managed through environment-level secrets stores and never hardcoded into application code.
No Sensitive Data in Logs
PII-SafeStructured log output is sanitized before emission. PII and financial data are excluded from application logs, SIEM events, and error traces.
Tamper-aware records for every action
The audit layer captures every authenticated action with integrity markers suitable for forensic review and supervisory examination. Records are append-only — no user, including administrators, can modify or delete an audit entry.
- Append-only records — no modification or deletion of audit entries
- Hash chain integrity verification — tamper detection on every record
- Coverage for logins, role changes, case actions, rule edits, and entity registry changes
- Analyst attribution on every note, disposition, escalation, and closure
- Filterable search by user, entity, date, and action type
- Export subsets for regulator or legal workflows in CSV or JSON
- Configurable retention policy with secure archival
Audit log coverage
Fits your network topology
Caspix is containerized and can run on-premises, in private cloud, or as managed infrastructure — with no compromise on security posture across any deployment model.
Deploy entirely within your network perimeter. No outbound data requirements. Compatible with air-gapped environments.
Containerized deployment on your own cloud infrastructure (AWS, Azure, GCP). Full control over data residency and network egress.
Caspix manages infrastructure, updates, and monitoring. Data hosted in Kenya-based cloud infrastructure where applicable.
The platform can operate without internet connectivity. Telco enrichment falls back gracefully when external APIs are unreachable.
Designed for CBK regulatory expectations
The platform's audit trail, RBAC structure, case management workflow, and reporting outputs are designed with CBK and FRC supervisory requirements in mind. Institutions conducting security diligence can request a detailed technical security brief from the team.
Questions about deployment or security architecture?
We are happy to walk through security controls, deployment topology, and data handling in detail with your IT and security teams.